This English version is a translation provided for reference purposes only. In case of any discrepancy, the Portuguese version shall prevail.
1. Introduction
CryptoAssist ("we," "our," or "Platform") is committed to protecting the privacy and personal data of its users ("you"). This Privacy Policy describes what data we collect, how we use it, with whom we share it, and what your rights are, in compliance with Brazil's General Data Protection Law (Lei n. 13.709/2018 — LGPD).
2. Data Collected
We collect the following personal data:
- Authentication data: email address and display name obtained via Google Authentication.
- Portfolio data: cryptocurrency exchange API keys (stored in encrypted form), balances, and transaction history imported from connected exchanges.
- User preferences: favorite coins, alert settings, visual theme, and language.
- Usage data: access logs, device type, and browser information, for security and service improvement purposes.
3. Purpose of Processing
We use your personal data to:
- Manage cryptocurrency portfolios and display consolidated balances.
- Send customized alerts about price changes, volume, and market events.
- Display real-time market data relevant to your preferences.
- Provide cryptocurrency news and analysis filtered by relevance.
- Continuously improve the service and resolve technical issues.
4. Data Sharing
We do not share your personal data with third parties. Your data is used exclusively to provide the CryptoAssist service. We do not sell, rent, or transfer your data to business partners, advertisers, or any other entities.
Exceptions apply only when there is a legal obligation or court order requiring us to disclose information.
5. Storage and Security
Your data is stored on secure servers with encryption in transit (TLS 1.2+) and at rest. Exchange API keys are stored using AES-256 encryption and managed via a secrets vault (HashiCorp Vault).
We implement strict access controls, intrusion monitoring, and periodic security audits.
6. Data Retention
Your personal data is retained for as long as your account remains active. After account deletion, your data will be removed from our systems within 30 (thirty) days, except where retention is required by legal or regulatory obligations.
7. Your Rights (LGPD)
Under the LGPD, you have the following rights with respect to your personal data:
- Access: request information about what personal data we hold about you.
- Rectification: request the correction of incomplete, inaccurate, or outdated data.
- Deletion: request the deletion of your personal data processed on the basis of your consent.
- Portability: request the transfer of your data to another service provider.
- Withdrawal of consent: withdraw your consent at any time, without affecting the lawfulness of processing carried out prior to such withdrawal.
8. Cookies and Similar Technologies
We use cookies for secure session authentication, consent management, and referral tracking. The table below describes each cookie used by the Platform:
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
| ca_cookie_consent | Stores the user's cookie consent choice | 1 year | Essential |
| ca_access_token | Session authentication token | Session | Essential |
| ca_referral_code | Referral tracking (cleared automatically after use) | 30 days | Functional |
| _ga, _ga_* | Google Analytics 4 — anonymous usage analytics | 2 years | Analytics |
Analytics cookies (_ga, _ga_*) are activated only after the user accepts the cookie consent banner. You can withdraw this consent at any time by clicking "Manage cookies" in the Platform footer.
9. Google Analytics 4
We use Google Analytics 4 (GA4) to collect anonymous usage statistics for the Platform. This information helps us understand how users interact with CryptoAssist and continuously improve the product.
Data collected by GA4:
- Page views and navigation between screens
- Feature usage events (e.g., opening an alert, connecting an exchange)
- Device type and browser
- Country of origin (country-level only, not precise location)
No personally identifiable information (PII) — such as name, email, or financial data — is sent to Google. Tracking is based on anonymous identifiers generated by GA4.
GA4 data collection occurs only with the user's consent. You may decline or withdraw consent at any time through the cookie consent banner.
10. Referral System
CryptoAssist offers a voluntary referral program. When participating:
- You receive an anonymized referral code in the format
CRYPTO-XXXX, which contains no personal data. - When someone signs up using your code, no personal data is shared between you and the referred user, or vice versa.
- We only track the referral count and the status of each referral (pending / completed).
- The
ca_referral_codecookie is automatically cleared after use (completed registration).
11. Crypto Tax Calculator
The cryptocurrency tax calculator available at /imposto-cripto operates 100% client-side (in the user's browser):
- No tax data, income data, or calculation results are transmitted to our servers.
- All calculations happen locally in the user's browser.
- CryptoAssist does not store any financial information entered in the calculator.
12. Push Notifications
Push notifications are entirely optional and require explicit browser or device permission:
- You control which categories you wish to receive: morning briefing, Fear & Greed changes, portfolio updates, and breaking news.
- You can disable notifications at any time in Settings > Notifications.
- You may also revoke permission directly in your browser or operating system settings.
13. Contact
To exercise your rights or for questions about this Privacy Policy, please contact our Data Protection Officer (DPO):
14. Changes to This Policy
We may update this Privacy Policy periodically. Significant changes will be communicated via email or notification on the Platform. The most recent version will always be available on this page.